Impact
A missing permission check in the Telephony component of MediaTek chipsets can allow local actors to read protected data without needing additional privileges. Because the flaw does not require any prior exploitation of the device, the impact is strictly the disclosure of sensitive local information to a user or process that gains access to the vulnerable module.
Affected Systems
The vulnerability is present in MediaTek, Inc. MediaTek chipset devices that include the Telephony functionality. No specific build or firmware versions are listed, so any system that incorporates the affected Telephony component is potentially exposed.
Risk and Exploitability
The CVSS score of 6.2 indicates medium severity, and the EPSS score of < 1% shows a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation reports to date. However, the flaw can be triggered locally with no user interaction, so the likelihood of exploitation depends on the presence of the vulnerable component and the attacker’s physical or local access. Using the provided patch ID and applying the vendor supplied fix will eliminate the risk.
OpenCVE Enrichment